Oval Definition:oval:org.mitre.oval:def:24182
Revision Date:2014-05-26Version:26
Title:ELSA-2014:0015: openssl security update (Important)
Description:The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2013-4353
CVE-2013-6449
CVE-2013-6450
ELSA-2014:0015-00
Platform(s):Oracle Linux 6
Product(s):openssl
Definition Synopsis
  • Oracle Linux 6.x
  • AND rpm test
  • openssl-devel is earlier than 0:1.0.1e-16.el6_5.4
  • OR openssl is earlier than 0:1.0.1e-16.el6_5.4
  • OR openssl-perl is earlier than 0:1.0.1e-16.el6_5.4
  • OR openssl-static is earlier than 0:1.0.1e-16.el6_5.4
  • BACK